Red Hat Security Advisory: RHOAI 2.25.7 - Red Hat OpenShift AI
Release of RHOAI 2.25.7 provides these changes:
AI Analysis
Technical Summary
CVE-2025-14813 is a cryptographic vulnerability in the BC-JAVA bcprov library's GOSTCTR implementation used by Red Hat products including OpenShift Dev Spaces. The GOSTCTR cipher reuses keystream after encrypting more than 255 blocks, violating fundamental confidentiality guarantees. An attacker who captures ciphertext encrypted beyond this limit can perform cryptanalysis to recover plaintext data. The vulnerability impacts confidentiality but not integrity or availability. Red Hat's advisory highlights the need to limit encryption payload size or transition to a secure authenticated encryption mode. No explicit patch or fix is currently provided; mitigation is procedural.
Potential Impact
The vulnerability allows attackers to break the confidentiality of data encrypted with the GOSTCTR implementation after more than 255 blocks are processed under the same key and IV. This can lead to full recovery of plaintext from ciphertext, compromising sensitive communications or stored data. There is no impact on data integrity or availability. No known exploits are reported in the wild. The severity is high due to the potential for complete data exposure.
Mitigation Recommendations
Currently, no official patch or fix is confirmed for this vulnerability. To mitigate the risk, users must strictly limit the amount of data encrypted under a single key and IV pair to a maximum of 255 blocks when using the GOSTCTR implementation. Alternatively, users should transition to a more secure, standardized, and authenticated encryption mode to avoid keystream reuse. Monitor Red Hat advisories for updates or patches addressing this issue.
Red Hat Security Advisory: RHOAI 2.25.7 - Red Hat OpenShift AI
Description
Release of RHOAI 2.25.7 provides these changes:
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-14813 is a cryptographic vulnerability in the BC-JAVA bcprov library's GOSTCTR implementation used by Red Hat products including OpenShift Dev Spaces. The GOSTCTR cipher reuses keystream after encrypting more than 255 blocks, violating fundamental confidentiality guarantees. An attacker who captures ciphertext encrypted beyond this limit can perform cryptanalysis to recover plaintext data. The vulnerability impacts confidentiality but not integrity or availability. Red Hat's advisory highlights the need to limit encryption payload size or transition to a secure authenticated encryption mode. No explicit patch or fix is currently provided; mitigation is procedural.
Potential Impact
The vulnerability allows attackers to break the confidentiality of data encrypted with the GOSTCTR implementation after more than 255 blocks are processed under the same key and IV. This can lead to full recovery of plaintext from ciphertext, compromising sensitive communications or stored data. There is no impact on data integrity or availability. No known exploits are reported in the wild. The severity is high due to the potential for complete data exposure.
Mitigation Recommendations
Currently, no official patch or fix is confirmed for this vulnerability. To mitigate the risk, users must strictly limit the amount of data encrypted under a single key and IV pair to a maximum of 255 blocks when using the GOSTCTR implementation. Alternatively, users should transition to a more secure, standardized, and authenticated encryption mode to avoid keystream reuse. Monitor Red Hat advisories for updates or patches addressing this issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:17668
- Cve Count
- 23
- Additional Cves
- ["CVE-2025-67030","CVE-2026-0636","CVE-2026-2332","CVE-2026-3505","CVE-2026-5588","CVE-2026-5795","CVE-2026-6857","CVE-2026-22731","CVE-2026-27446","CVE-2026-33453","CVE-2026-33454","CVE-2026-33870","CVE-2026-33871","CVE-2026-35554","CVE-2026-40022","CVE-2026-40453","CVE-2026-40858","CVE-2026-40860","CVE-2026-40972","CVE-2026-40973","CVE-2026-40975","CVE-2026-41635"]
- State
- PUBLISHED
Threat ID: 6a160958e29bf47b5061fbc1
Added to database: 05/26/2026, 20:58:00 UTC
Last enriched: 08/14/2026, 19:51:28 UTC
Last updated: 09/15/2026, 01:37:29 UTC
Views: 183
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.